Inferno, which sdrapkin cited as an example of crypto done right, offers this API:
public static byte[] Encrypt(byte[] masterKey, ArraySegment<byte> plaintext, ArraySegment<byte>? salt = null)
The docs suggest:
The "salt" parameter can include Additional Data (AD) or its hash - which will also be authenticated.
This is, in my opinion, not okay as a high-level easy-to-use primitive, as it leaks information if you don't properly use the salt.
EDIT: I read the source (https://github.com/sdrapkin/SecurityDriven.Inferno/blob/mast...), and Inferno's primitive is randomized. This avoids the info leak, but it's likely to be a decent amount slower as a result, and the primitive needs a good RNG. As a result, it might be vulnerable to failure if the application uses fork(), it's awkward to implement on some embedded platforms, etc.
The point of nonce-misuse-resistant encryption is to reduce the damage from nonce reuse, not to give you an excuse to ignore nonces entirely for encryption of arbitrary data.